List of Bandolier Audit Files

From SCADApedia

Jump to: navigation, search

Bandolier helps asset owners and vendors identify and audit optimal security configuration for control system servers and workstations. In this Department of Energy funded project, Digital Bond partners with leading control system application vendors to establish practical security configuration guidance for SCADA, DCS, and other industrial control system components. Digital Bond then creates and distributes specialized security audit files that can be used with the Nessus vulnerability scanner. Bandolier, in conjunction with Nessus, is the most widely used security tool in industrial control systems.

Below is the list of Bandolier audit files and their current status.


Vendor Application Name Version Operating System Status
ABBRanger RDAS2003Tru64 UNIX1.0
ABBRanger RAS2003Tru64 UNIX1.0
ABBRanger Web Server2003Tru64 UNIX1.0
ABBRanger Workstation2003Windows XP1.0
ABB800xA PPA Connectivity Server5.xWindows Server 2003Development
ABB800xA PPA Aspect Server5.xWindows Server 2003Development
ABB800xA PPA Historian 5.xWindows Server 2003Development
ABB800xA PPA Domain Controller 5.xWindows Server 2003Development
ABB800xA PPA Eng/Operator Workplace 5.xWindows XPDevelopment
AREVAe-terraplatform (Production Server)2.5Windows Server 20031.0
AREVAe-terraplatform (Production Server)2.5Red Hat Linux 5.31.0
AREVAe-terrabrowser (Web Display Server)3.5Windows Server 2003 (IIS v6)1.0
AREVAe-terrabrowser (Web Display Server)3.5Red Hat Linux 5.3 (Apache v2.0)1.0
AREVAe-terrabrowser (Client)3.5Windows XP1.0
EmersonOvation Engineering Station3.1 FamilyWindows XPBeta
EmersonOvation Operator Workstation3.1 FamilyWindows XPBeta
EmersonOvation Process Historian3.1 FamilyWindows Server 2003Beta
EmersonOvation SCADA Communication Server3.1 FamilyWindows Server 2003Beta
InvensysWonderware10.0Windows Server 2003Development
MatrikonSecurity Gateway/TunnellerWindows Server 20031.0
OSIsoftPI Enterprise Server3.3.x-3.4.xWindows Server 20031.0
SiemensSpectrum Power TG SCADA Host 8.2Red Hat Linux1.0
SiemensSpectrum Power TG SCADA Workstation8.2Windows XP1.0
SiemensSiemens Spectrum Power TG Web Console 8.2Windows Server 20031.0
SNC-Lavalin ECS GENe SCADARed Hat Linux1.0
TelventOASyS DNA Realtime Server7.5Windows Server 20031.0
TelventOASyS DNA Historian7.5Windows Server 20031.0
TelventOASyS DNA XOS7.5Windows XP1.0
TelventOASys DNA Engineering Station7.5Windows Server 20031.0

Rights and Restrictions

Digital Bond creates two Bandolier Security Audit Files for each control system component. The .App file was developed by Digital Bond, Inc. This Bandolier Security Audit File is the sole property of Digital Bond, Inc., and Digital Bond retains full ownership rights to this file.

The OS file is a modified version of a .audit file originally written and maintained by Tenable Network Security, www.tenablesecurity.com . The original .audit file is copyright Tenable Network Security. Tenable has granted Digital Bond permission to make modifications to the original .audit file, to produce an updated .audit file, and to distribute this updated .audit file to its customers and partners. Tenable and Digital Bond maintain a collective ownership of this updated .audit file, called a Bandolier Security Audit File for OS checks.

Digital Bond is providing the Bandolier Security Audit File "as is" without: (1) any warranties to the effectiveness or accuracy or (2) the responsibility to make or notify you of any bug fixes or updates of any kind.

Restriction: The Bandolier Security Audit Files or any derivative of these files shall not be posted on any website, bulletin board, ftp server, newsgroup, or other similar mechanism or device without the prior written consent of Digital Bond, Inc.

See Also

Bandolier

Bandolier and NERC CIP

Bandolier Audit Check Examples

Bandolier Severity Ratings

Bandolier User Guide for Nessus

External links

Download Bandolier Security Audit Files

Bandolier Two-Page Brochure

Nessus Compliance Checks FAQ

Personal tools